<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VA 7.1 using HTTPS in SAS Visual Analytics</title>
    <link>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146031#M328</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have installed VA 7.1 SMP, the mid tier is configured to use HTTPS, we use a certificate signed by Thwate. I am having a problem when trying to start the LASR Server, I get the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: Unable to register LASR server with authentication service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup the SSLCALISTLOC option for the SAS Workspace to correctly point to the pem certificate used by the SAS Web Server but I end up with the same error, I have also created a certficate with all the certificates in the CA path and again I get the same error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAS Tech Support have suggested to change the protocol to HTTP for just the SASLASRAuthorization endpoint, which I have done. I have changed the LASR Auth service definition in the Metadata and also added a RewriteRule to the Web Server configuration so that all services but SASLASRAuthorization are redirected to HTTPS if called with HTTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way I can start the LASR Server from SAS SAS BASE or EG, but I get a different error from within the web applications, related to spring CAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2014-10-27 15:38:09,224 [tomcat-http--25] ERROR org.jasig.cas.CentralAuthenticationServiceImpl - ServiceTicket [ST-37-xdZfcI6wAdiJF0jvL9bl-cas] with service [&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://hostname/SASLASRAuthorization/rest/servers/details"&gt;http://hostname/SASLASRAuthorization/rest/servers/details&lt;/A&gt;&lt;SPAN&gt; does not match supplied service [&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://hostname/SASLASRAuthorization/rest/servers/details"&gt;https://hostname/SASLASRAuthorization/rest/servers/details&lt;/A&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2014-10-27 15:38:09,228 [tomcat-http--45] ERROR [ST-29-l5Wxwhx76DgPCMubXvYZ-caslsradmin] com.sas.lasr.mgmt.client.serviceproxy.LasrMgmtServiceProxy - &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://hostname/SASLASRAuthorization/rest/servers/details?ticket=ST-37-xdZfcI6wAdiJF0jvL9bl-cas"&gt;http://hostname/SASLASRAuthorization/rest/servers/details?ticket=ST-37-xdZfcI6wAdiJF0jvL9bl-cas&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2014-10-27 15:38:09,228 [tomcat-http--45] ERROR [ST-29-l5Wxwhx76DgPCMubXvYZ-caslsradmin] com.sas.lasr.mgmt.client.serviceproxy.LasrMgmtServiceProxy - org.springframework.web.client.HttpClientErrorException: 401 Unauthorized&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With versions 6.x of VA I never had this problem, all was working with just the standard certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone any idea? I am stuck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Frances&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Oct 2014 15:46:21 GMT</pubDate>
    <dc:creator>franz</dc:creator>
    <dc:date>2014-10-28T15:46:21Z</dc:date>
    <item>
      <title>VA 7.1 using HTTPS</title>
      <link>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146031#M328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have installed VA 7.1 SMP, the mid tier is configured to use HTTPS, we use a certificate signed by Thwate. I am having a problem when trying to start the LASR Server, I get the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: Unable to register LASR server with authentication service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup the SSLCALISTLOC option for the SAS Workspace to correctly point to the pem certificate used by the SAS Web Server but I end up with the same error, I have also created a certficate with all the certificates in the CA path and again I get the same error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAS Tech Support have suggested to change the protocol to HTTP for just the SASLASRAuthorization endpoint, which I have done. I have changed the LASR Auth service definition in the Metadata and also added a RewriteRule to the Web Server configuration so that all services but SASLASRAuthorization are redirected to HTTPS if called with HTTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way I can start the LASR Server from SAS SAS BASE or EG, but I get a different error from within the web applications, related to spring CAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2014-10-27 15:38:09,224 [tomcat-http--25] ERROR org.jasig.cas.CentralAuthenticationServiceImpl - ServiceTicket [ST-37-xdZfcI6wAdiJF0jvL9bl-cas] with service [&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://hostname/SASLASRAuthorization/rest/servers/details"&gt;http://hostname/SASLASRAuthorization/rest/servers/details&lt;/A&gt;&lt;SPAN&gt; does not match supplied service [&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://hostname/SASLASRAuthorization/rest/servers/details"&gt;https://hostname/SASLASRAuthorization/rest/servers/details&lt;/A&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2014-10-27 15:38:09,228 [tomcat-http--45] ERROR [ST-29-l5Wxwhx76DgPCMubXvYZ-caslsradmin] com.sas.lasr.mgmt.client.serviceproxy.LasrMgmtServiceProxy - &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://hostname/SASLASRAuthorization/rest/servers/details?ticket=ST-37-xdZfcI6wAdiJF0jvL9bl-cas"&gt;http://hostname/SASLASRAuthorization/rest/servers/details?ticket=ST-37-xdZfcI6wAdiJF0jvL9bl-cas&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2014-10-27 15:38:09,228 [tomcat-http--45] ERROR [ST-29-l5Wxwhx76DgPCMubXvYZ-caslsradmin] com.sas.lasr.mgmt.client.serviceproxy.LasrMgmtServiceProxy - org.springframework.web.client.HttpClientErrorException: 401 Unauthorized&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With versions 6.x of VA I never had this problem, all was working with just the standard certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone any idea? I am stuck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Frances&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 15:46:21 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146031#M328</guid>
      <dc:creator>franz</dc:creator>
      <dc:date>2014-10-28T15:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: VA 7.1 using HTTPS</title>
      <link>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146032#M329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI, this was fixed. Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Dec 2014 14:36:57 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146032#M329</guid>
      <dc:creator>franz</dc:creator>
      <dc:date>2014-12-18T14:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: VA 7.1 using HTTPS</title>
      <link>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146033#M330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Francesco,&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;how&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;did you solve&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;this problem&lt;/SPAN&gt;? &lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;I would be interested&lt;/SPAN&gt; for same activity&lt;/P&gt;&lt;P&gt;Thank's&lt;/P&gt;&lt;P&gt;Sergio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Dec 2014 16:50:19 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146033#M330</guid>
      <dc:creator>dursergio</dc:creator>
      <dc:date>2014-12-18T16:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: VA 7.1 using HTTPS</title>
      <link>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146034#M331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please let us know how you fixed the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2015 10:06:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146034#M331</guid>
      <dc:creator>shatrughan</dc:creator>
      <dc:date>2015-02-25T10:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: VA 7.1 using HTTPS</title>
      <link>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146035#M332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My certificate is signed by Thwate, ie an "official" certificates provider, this means the root and intermediate certificates are already installed on the system (in my case RHEL) when you install openSSL so I pointed SAS to the certificate bundle that comes with openSSL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;To confirm the correct location of the certicates bundle, o&lt;/SPAN&gt;n your system type&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@srvname certs]# openssl version -d&lt;/P&gt;&lt;P&gt;OPENSSLDIR: "/etc/pki/tls"&lt;/P&gt;&lt;P&gt;[root@&lt;SPAN style="font-size: 13.3333330154419px;"&gt;srvname &lt;/SPAN&gt;certs]# pwd&lt;/P&gt;&lt;P&gt;/etc/pki/tls/certs&lt;/P&gt;&lt;P&gt;[root@&lt;SPAN style="font-size: 13.3333330154419px;"&gt;srvname &lt;/SPAN&gt;certs]# ls -l&lt;/P&gt;&lt;P&gt;total 1768&lt;/P&gt;&lt;P&gt;-rw-r--r--. 1 root root 786601 Jun 24 11:22 ca-bundle.crt&lt;/P&gt;&lt;P&gt;-rw-r--r--. 1&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;root root 1005005 Jun 24 11:22 ca-bundle.trust.crt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then in SAS cfg file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/sas/SASHome/SASFoundation/9.4/sasv9_local.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add the following line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-sslcalistloc /etc/pki/tls/certs/ca-bundle.trust.crt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and that's it. Note that you can add the sslcalistloc in other cfg files, I added it to the foundation cfg file because that way it's picked up by all SAS processes, regardless of their class (ie workspace, stp server, olap and so on).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAS documentation is not very clear and I find it misleading in cases like this where the certificate is not self-signed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps, regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2015 13:19:38 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146035#M332</guid>
      <dc:creator>franz</dc:creator>
      <dc:date>2015-02-25T13:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: VA 7.1 using HTTPS</title>
      <link>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146036#M333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi francesco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried your suggestions but I am still not able to start my lasr server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: OpenSSL error 336134278 (0x14090086) occurred in SSL_connect/accept at&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; line 4827, the error message is "error:14090086:SSL&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed".&lt;BR /&gt;ERROR: Encryption run-time execution error&lt;/P&gt;&lt;P&gt;ERROR: Unable to register LASR server with authentication service.&lt;BR /&gt;NOTE: The SAS System stopped processing this step because of errors.&lt;BR /&gt;NOTE: PROCEDURE LASR used (Total process time):&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; real time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.77 seconds&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cpu time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.04 seconds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea on this error. My sasv9_local.cfg file is point towards /etc/pki/tls/certs/ca-bundle.trust.crt .&lt;/P&gt;&lt;P&gt;I infact tried setting SSLCALISTLOC variable to all sort of cert available like .pem, .csr, .crt etc. but nothing worked for me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Mar 2015 05:28:11 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146036#M333</guid>
      <dc:creator>shatrughan</dc:creator>
      <dc:date>2015-03-17T05:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: VA 7.1 using HTTPS</title>
      <link>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146037#M334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had exactly the same problem and I am using a self signed certificate. The problem was resolved by pointing the -sslcalistloc option to the PEM encoded certificate that is being used by the SAS Web Server. After doing that, it all worked perfectly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Mar 2015 09:35:21 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146037#M334</guid>
      <dc:creator>cj_blake</dc:creator>
      <dc:date>2015-03-21T09:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: VA 7.1 using HTTPS</title>
      <link>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146038#M335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, yes this is the way described in the SAS Documentation and it works just fine, my answer is applicable for certificates signed by an external CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2015 13:42:32 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Visual-Analytics/VA-7-1-using-HTTPS/m-p/146038#M335</guid>
      <dc:creator>franz</dc:creator>
      <dc:date>2015-03-25T13:42:32Z</dc:date>
    </item>
  </channel>
</rss>

